Andy Yen: Think your email's private? Think again

  Рет қаралды 356,694

TED

TED

9 жыл бұрын

Sending an email message is like sending a postcard, says scientist Andy Yen in this thought-provoking talk: Anyone can read it. Yet encryption, the technology that protects the privacy of email communication, does exist. It's just that until now it has been difficult to install and a hassle to use. Showing a demo of an email program he designed with colleagues at CERN, Yen argues that encryption can be made simple to the point of becoming the default option, providing true email privacy to all.
TEDTalks is a daily video podcast of the best talks and performances from the TED Conference, where the world's leading thinkers and doers give the talk of their lives in 18 minutes (or less). Look for talks on Technology, Entertainment and Design -- plus science, business, global issues, the arts and much more.
Find closed captions and translated subtitles in many languages at www.ted.com/talks/andy_yen_thi...
Follow TED news on Twitter: / tednews
Like TED on Facebook: / ted
Subscribe to our channel: / tedtalksdirector

Пікірлер: 421
@BtcfeedNetNews
@BtcfeedNetNews 8 жыл бұрын
Great TED talk. I can't agree more with the statement "We need to support a different business model for the internet, one which doesn't rely entirely on advertisements for revenue and for growth"
@TheSonicfan129
@TheSonicfan129 4 жыл бұрын
I agree that advertisement for a company is important, but many marketers use their gift to change viewpoints in opinions and facts, and control what you see on the internet. That is what is very dangerous, and should be avoided.
@ninjamaster224
@ninjamaster224 8 жыл бұрын
so the public key is the "locking" mechanism, and the private key is the "unlocking" mechanism. a user has both the locker and the unlocker, and can give out the locker to anyone, but keeps the unlocker safe.
@crowbartender
@crowbartender 9 жыл бұрын
10:00 They have users in North Korea. That's pretty impressive.
@pmAdministrator
@pmAdministrator 4 жыл бұрын
Yea, Im one of them! Send hjelp, btw.
@jasonk7675
@jasonk7675 4 жыл бұрын
Administrator i find this funny, but awful at the same time.
@lmaolmfao3611
@lmaolmfao3611 4 жыл бұрын
@Peter if you are in russian, don't use mail.ru Here's their article on the russian ban: protonmail.com/blog/russia-block/
@Eli-gn6dr
@Eli-gn6dr 3 жыл бұрын
@Peter Use PM through a non-Russia based VPN over Tor, so your ISP doesn't know your using tor.
@strengthxphilosophy
@strengthxphilosophy 9 жыл бұрын
In 10 years our kids will be like; ''privacy'' ? is that something you can eat?
@rapalarm5212
@rapalarm5212 9 жыл бұрын
truth :p
@curtismega7591
@curtismega7591 9 жыл бұрын
If you print out a picture of someone's personal information and eat it, then yes.
@liegebeestje7903
@liegebeestje7903 6 жыл бұрын
i hope blockchain will provide this
@captainnemonadie6541
@captainnemonadie6541 6 жыл бұрын
And it's up to you to teach them differently.. “Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say.” ... Snowden
@ITILII
@ITILII 4 жыл бұрын
They'll ask the same question about what's called "food"
@rawstarmusic
@rawstarmusic 9 жыл бұрын
Amazing talk Andy. First of all you understand that we need privacy to live in a free world which most people don't. The invention of privacy in communication is necessary for a future worthy of human kind.
@martin_green
@martin_green 9 жыл бұрын
If private end to end encryption could be adopted by our current email providers (Microsoft, Google, etc), I would gladly pay an annual subscription for email. The big players should give us the choice to either serve us with ads etc. for free OR provide us with total privacy for a fee, rather than signing up for yet another email account based on specific (possibly temporary) features.
@ajnikhil
@ajnikhil 7 жыл бұрын
They earn from ads way more than they will from subscription but they should definitely give the option. Still 90% people don't understand how vulnerable they are but soon breach of privacy might become their concern.
@skaltura
@skaltura 5 жыл бұрын
and in the fineprint they would still reserve rights to look into your data X)
@noxxi
@noxxi 7 жыл бұрын
Give me ProtonEVERYTHING!
@oleksiyalkhazov9201
@oleksiyalkhazov9201 5 жыл бұрын
The ProtonUnix OS, a beloved hybrid of privacy and efficiency.
@mafib1
@mafib1 5 жыл бұрын
ProtonOS 🤔
@jpbochi
@jpbochi 4 жыл бұрын
working on it. :)
@drk_blood
@drk_blood 2 жыл бұрын
You comment didn't aged well. I wonder if you know why..
@MajorEasley
@MajorEasley 2 жыл бұрын
.. go I have since proven not to be as private since the Ukrainian war started they have been sharing information that they would otherwise consider private.
@someoneelse.2252
@someoneelse.2252 8 жыл бұрын
Some smart teacher should show this to his class.
@billypuntove
@billypuntove 5 жыл бұрын
Can someone tell me the names of the companies that are without name (logo only) in the picture? I think I only regonize Telegram out of them all. They're @11:00
@JovannyARodriguez
@JovannyARodriguez 9 жыл бұрын
*PRIVACY LOVERS,* you are going to love this!
@oleksiyalkhazov9201
@oleksiyalkhazov9201 5 жыл бұрын
Thank you for the ProtonMail and a great speech!
@ConnorMarc
@ConnorMarc 6 жыл бұрын
Good stuff. I'm finally creating my ProtonMail account, like a year later than I said I would.
@Nithyanandan.S
@Nithyanandan.S 8 жыл бұрын
finally got the secured mail from you thanks a lot.... started using from now
@upfulsoul826
@upfulsoul826 9 жыл бұрын
Best TED talk in a while.
@elliejordan2033
@elliejordan2033 4 жыл бұрын
I have chosen Utopia for more than six months, and I am very happy about It. Never failed in my needs.
@Tango_November
@Tango_November 9 жыл бұрын
So happy I got my ProtonMail when it first started up.
@saywhat4229
@saywhat4229 7 жыл бұрын
Great speech! This should've got more views !!
@uvlight2211
@uvlight2211 5 ай бұрын
I cannot believe that I did not find this earlier ! Spot On!
@user-rm4jf6tu2n
@user-rm4jf6tu2n 8 жыл бұрын
Congratulations and thanks for help the world more free! :-D Greetings from Brazil.
@M3talOD
@M3talOD 2 жыл бұрын
Here 7 years later . Just implemented the name and overhaul . PROTON ! EVERYTHING! Support and stand for something . Direct or indirect this issue affects us all . Don’t dismiss what you don’t understand and don’t shrug it off because it is something you think hasn’t affected you . IT HAS !
@mcgman8058
@mcgman8058 4 жыл бұрын
Andy thank you so much !
@22owl
@22owl 6 жыл бұрын
What are the names of the other programs at the end? The ones that don't have the names listed of course.
@jesshurun
@jesshurun 9 жыл бұрын
That's why you should use the TOR Network. For email and all your web browsing needs!
@buddy77587
@buddy77587 9 жыл бұрын
Wonderful, just wonderful!
@cambarker4267
@cambarker4267 2 жыл бұрын
Hi Andy, very good presentation sir. I have a question. Isn't telegrams CEO part of or connected to the WEF?
@GaskellleoCinema
@GaskellleoCinema 8 жыл бұрын
I don't know if I agree with this project - if the user doesn't know how the encryption works, how can they possibly have confidence in it? I think a better way to approach this issue is to educate people about how encryption works and why they should use it.
@bjarkeslater
@bjarkeslater 9 жыл бұрын
What are the names of the "projects" behind all the logos he shows? Some don't have name in the logo. That's why I'm asking.
@alejandrajoyaramos4933
@alejandrajoyaramos4933 9 жыл бұрын
TED me parece lo mas genial que he encontrado ... pero se los agradecería si le pusieran subtítulos!!! Gracias")
@MissBrendaLeeGertman
@MissBrendaLeeGertman 3 жыл бұрын
Thank you!
@Shmagalag
@Shmagalag 8 жыл бұрын
Well, here goes another comment that the creepy internet is going to store in my secret cyber diary.
@VikashPrasadhyperbolic
@VikashPrasadhyperbolic 9 жыл бұрын
well i dont know about the hassle involved in encrypting long messages but for small ones you can just tell the other person to use a cipher. Its the same kind of encryption method but on a lower scale.
@theslimeylimey
@theslimeylimey 9 жыл бұрын
Isn't this pretty much how PGP works with a public and private key system?
@MrIosonoleggenda
@MrIosonoleggenda 9 жыл бұрын
Somewhat. With PGP you have more control about how the data is encrypted and who you trust but it takes knowledge to use properly. ProtoMail abstracts that between ProtoMail emails.
@HigherPlanes
@HigherPlanes 9 жыл бұрын
That's exactly how PGP works.
@TheHarmont
@TheHarmont 9 жыл бұрын
theslimeylimey Looks like the basic public/private key authentication that's being extensively used throughout the Internet. Didn't really get how ProtoMail is different.
@AlexRosier
@AlexRosier 9 жыл бұрын
Yes, ProtonMail is built upon an OpenPGP framework. The difference how easy it is to use, I don't have to explain to my grandma/mother/friend/coworker/business contact how to setup their public/private key pair.
@HigherPlanes
@HigherPlanes 9 жыл бұрын
Alex Rosier Really though, I'm tech savy and it even took me quite a bit of reading to understand PGP. But once the concept of private key/public keys sharing clicks in your mind, it's pretty simple and just a matter of entering different commands.
@BOBOUDA
@BOBOUDA 9 жыл бұрын
If you guys still don't know Duckduckgo, please give it a try... it's better than google in so many ways; privacy, search results (sometimes), and especially there's many useful ways to make custom searches on specific websites with it.
@HiAdrian
@HiAdrian 9 жыл бұрын
So they simply make their money by non-targeted ads? If so that certainly sounds a lot better than Google & Co.
@BOBOUDA
@BOBOUDA 9 жыл бұрын
***** Hope you like it. you can make searches on specific websites from the search bar if you set it as your main search engine; for example to make automatically a search on KZfaq you can type what you want to find on youtube and "!yt" to get directly the youtube results. Works also with google image !gi, google translate !gt, wikipedia !w and many others.
@PixelPhobiac
@PixelPhobiac 9 жыл бұрын
Or use startpage.com if you're addicted to Google's algorithm.
@BOBOUDA
@BOBOUDA 9 жыл бұрын
***** Saddly I don't know most of these websites or companies :/ I'm not an expert at all when it comes to websites that respect your privacy, but I heard about a few like Duckduckgo that I thought were really worth promoting.
@BOBOUDA
@BOBOUDA 9 жыл бұрын
***** Thanks :) i'll give them a look,
@maomxesoax2471
@maomxesoax2471 5 жыл бұрын
What we need is the secure exchange of one password. After that, then its the good old one time pad (with an extra twist :-)) and steganography. Working on it :-)
@user-gu8yh4gw9r
@user-gu8yh4gw9r 11 ай бұрын
Thank you
@nexus1g
@nexus1g 2 жыл бұрын
How do you decrypt a message on the receiving system when only the sending system has the key that was used to encrypt the message?
@c1jersey
@c1jersey 9 жыл бұрын
Around 7:40 and up he is pretty much describing how an enigma machine works except in a digital format.
@phase1995
@phase1995 3 жыл бұрын
7:57 Damn, using jQuery for encryption is just next level security!
@user-ql3ws5uz1d
@user-ql3ws5uz1d 9 жыл бұрын
how do u actually get on the waiting list for proton mail?
@mssaarahn
@mssaarahn 8 жыл бұрын
How would forwarding messages work, since everyone would need the same public key?
@darin4067
@darin4067 8 жыл бұрын
What program does he use for his slide show?
@littlebit670
@littlebit670 6 ай бұрын
I signed up for a Proton account for their VPN, but I might think about their other services too. Being completely dependent on Google is not the best idea :
@ShadowEspada
@ShadowEspada 9 жыл бұрын
This is a great idea, I hope it works, although there is a massive exponential amount data that corporations and governments have already collected.
@sebbes333
@sebbes333 8 жыл бұрын
6:56 is it possible to store the public key on the server? 7:06 so when Bob has made the email with Alice's email address and pressed Send, the client application sends a quarry to the server for the key that correspond to Alice's email, and then encrypts the message before sending the message to the server. The only security leak I can see is if for example the government replaces Alice's key with some kind of super special key that works for Alice and the government also has access too.
@TheSkepticSkwerl
@TheSkepticSkwerl 8 жыл бұрын
+Sion Creating a key with dual unlocks is impossible from my knowledge. The reason it takes a few minutes to generate the key is because it's so massive, that super computers can't decrypt it.
@snowe..
@snowe.. 8 жыл бұрын
+TheSkepticSkwerl +Sion It's actually not because it is a massive number, but more because it is a massive number based on massive primes. Look up Prime Factorization.
@destroya3303
@destroya3303 5 жыл бұрын
@@TheSkepticSkwerl do you know then where exactly this key is stored? It can't be on my computer because otherwise I wouldn't be able to access ProtonMail from multiple computers. So there must be more going on. I know for SSH, I have my SSH keys saved on my physical hard drive. Something different is going on with ProtonMail
@andreas1132
@andreas1132 9 жыл бұрын
"Think your email's private?" No i don't "Think again" what what it's private?
@chamex14
@chamex14 9 жыл бұрын
Making an internet without ads??? I would like it very much, but i believe it is like TV without ads, i simply don't see it!!! My point is, where people see an oportunity to make money, including big companies, they don't even think twice, so taking them out would be very dificult!!!
@t1993ct2006c
@t1993ct2006c 8 жыл бұрын
I believe ads should exist, but I do not think they should steal data. Ads would work with the non intrusive pagewrite:"" command
@ahmedal-obaidi8305
@ahmedal-obaidi8305 3 жыл бұрын
So much relevant today.
@drannoc100
@drannoc100 3 жыл бұрын
Another Asian American hero who’s so smart and confident, yet so humble. - This is as important as Steve Jobs’ iphone! Chinese? Korean? Doesn’t look Japanese for sure. Nevertheless, hope to see more Asian Americans get recognized.
@guitarsoundsaround
@guitarsoundsaround Жыл бұрын
And there’s the problem - you think Asian Americans are smarter? More gifted. Dump the race bs.
@christineblack4654
@christineblack4654 2 жыл бұрын
I have been using it for a long time now. starting to get many messages of companies of whom I have baught clothing from. still hoping it's safer tho.
@user-wp8yx
@user-wp8yx 9 жыл бұрын
I tend to get ads for products or services that I just purchased. It would be more helpful to get the add before I make the purchase. Think twice before you advertise with Google.
@josephjay2195
@josephjay2195 9 жыл бұрын
Do both parties have to use protonmail for email encryption to work?
@yashaswivunnava6699
@yashaswivunnava6699 4 жыл бұрын
Sadly, yes.
@IamRanJos
@IamRanJos 4 жыл бұрын
Extremely grey. Only if you're a technical genius can you get a legitimate answer.
@NikkiCaswell
@NikkiCaswell 9 жыл бұрын
Nothing's private anymore; whether it'd be your email, search engine, even text and phone calls. Thought many people knew this by now.
@DodgaOfficial
@DodgaOfficial 9 жыл бұрын
Thats what theyre trying to solve. The reason nothing is private is because people are careless, and companies have a motivation to invade your privacy. Things CAN be private but it requires the users to actually take steps to make it happen.
@preshisify
@preshisify 6 жыл бұрын
(Y)
@chaz-e
@chaz-e 9 жыл бұрын
How Bob can access the Public Key of Alice without the network or bypassing the Server?
@kimjameson7979
@kimjameson7979 9 жыл бұрын
Thanks Andy. Somewhere in a cloud of data, we're being linked together by virtue of my response. I hope they won't hold that against you. You're quite right in your observations and I admire your courage to speak out, but you might be already outnumbered because of say, funded storage capacity, intent, and yes the red herring, advertising revenue.
@gurmeet0108
@gurmeet0108 9 жыл бұрын
8:00 ... They also use sublime text....!!!
@weefeatures
@weefeatures 9 жыл бұрын
The subscriptions to zootube and publicdisgrace were a misunderstanding.
@glennsimkus
@glennsimkus 8 жыл бұрын
If proton mail is the way to go then they should have an internet security program with its own firewall and follow the same path as the bigger servers but with the added privacy and security as a bonus
@GummyRiches
@GummyRiches 9 жыл бұрын
This guy is up to something big. Bigger than google.
@harshadunofficial2721
@harshadunofficial2721 4 жыл бұрын
Which is better proton mail or tutanota
@narayanbhat3279
@narayanbhat3279 4 жыл бұрын
New internet! That reminded me of Richard from silicon valley
@kristinadrew4062
@kristinadrew4062 9 жыл бұрын
For a second i thought it was Filthy Frank in the thumbnail xD
@kudusodeko
@kudusodeko 7 жыл бұрын
Soon he will be
@SaberBenSalem
@SaberBenSalem 8 жыл бұрын
Someone help me please, can't figure out some of the projects which logos are at @11:02, thanks
@PetreTudor
@PetreTudor 8 жыл бұрын
+Saber Ben Salem last row, in the middle, it's Telegram. Pretty cool messaging app that works everywhere: android, apple, web, linux... But not 100% open source.
@PetreTudor
@PetreTudor 8 жыл бұрын
+Saber Ben Salem the black lock is Text Secure. A bit better that Telegram, not not as user friendly. I would add Red Phone.
@SaberBenSalem
@SaberBenSalem 8 жыл бұрын
+Petre Tudor Thank you so much, you've been really helpful ^^
@SaberBenSalem
@SaberBenSalem 8 жыл бұрын
+Saber Ben Salem So I summarize so far : ProtoNet, OwnCloud, SpiderOak DuckDuckGo, Bitcoin, ??? TOR, ProtonMail, TextSecure ???, Convergence, TOX ???, Telegram, BlackPhone still 3 projects i can't figure out
@jaafersa
@jaafersa 7 жыл бұрын
ProtoNet, OwnCloud, SpiderOak Duckduckgo, Bitcoin, Bleep TOR, Protonamil, TextSecure ChatSecure, Convergence, TOX Cryptocat, Telegram, BlackPhone
@thatspiritualhumane
@thatspiritualhumane 5 жыл бұрын
I think Proton Mail is doing a great job of encrypting & securing our data..
@juancamacholeon9444
@juancamacholeon9444 4 жыл бұрын
Great. Really nice. Protonmail. Let's go.
@redX1773
@redX1773 8 жыл бұрын
I really do not understand Andy Yen. He says that privacy is important and the server should not hold the encryption key (3:18). But ProtonMail is a web solution and it creates keys for me and also encrypts everything. Then the server has the encryption key. So what is the gain of using ProtonMail? Simply the promise that they say: "We are the good guys and we will encrypt your data"? And how the exchange of public keys and the verification process is done by ProtonMail? Because this is the most crucial part of the encryption process and what makes PGP hard to use. Every thing else is just tooling and anybody is able to do it. But a secure key exchange is the main problem and not addressed at all in this video. You emphasised that you work at CERN and a lot of very smart people have helped create ProtonMail. I really expected more of it ;(
@fyrye
@fyrye 8 жыл бұрын
+SoulTemptation Concept and my assumption is that the client creates the key pairs and performs the encryption or decryption using client-side code such as Javascript or Java. If you look at the code at 8:00, they were using jQuery/UI as the example of the software used to facilitate the client only concepts of key exchange. Hence the "may take up to 5 minutes and freeze your browser" message during account creation, as it generates the key pair. Where or how the key pair is saved to the client from the browser is unknown, maybe as an image? It also means changing your mailbox password, would require multiple days of CPU and network usage to propagate through even as little as a month of emails and attachments for most end-users and the amount of spam that is currently in circulation, since the MTAs and firewalls would no longer be able to prevent them.
@TOPhoenix
@TOPhoenix 8 жыл бұрын
+fyrye startcom's ssl process involves startcom issuing you a personal certification and installs it on your computer as personal cert so you use that to login and verify your identity and stuff. im sure its doing something similar. but if the keys are truly out of the server, than you would need to manually copy your cert/keys to every device that you are going to send and receive emails from.
@fyrye
@fyrye 8 жыл бұрын
+John Kim SSL is not used as it is used to encode the data on the client and decodes it on the server, protecting the encrypted data from man-in-the-middle attacks. Startcom is illuding to encrypting emails on the server relying on a key exchange from the client to encode/decode the data between peers.
@TOPhoenix
@TOPhoenix 8 жыл бұрын
+fyrye no i was just saying that the certs not on the server but it is installed on your computer so you would have to manually copy your cert or keys to all your devices. starcom was just an example.
@joeyj1631
@joeyj1631 5 жыл бұрын
He Chineeee
@husnainhaider3781
@husnainhaider3781 8 жыл бұрын
can proton mail users only send email to proton mail users?
@vishwapatel2138
@vishwapatel2138 9 жыл бұрын
But if you are ordering off of eBay,ect, do the people get your adress and credit card number?
@jmdennis1967
@jmdennis1967 3 жыл бұрын
A great message where today they are trying to limit free speach. Of course this has happened all over but is happening in places that were founded on free speach. This shows encryption between two people that probably have the same email provider but it would have been nice to see how this works say if I send an email to my sister that has gmail. More then likely it will not be encrypted on both ends.
@whatsinaname7828
@whatsinaname7828 5 жыл бұрын
It was refered to the ARPA Net when it was developed not CERN although there maybe scientists at CERN that worked on the ARPA Network. CERN is the largest band with user in the world.
@EugeneBuvard
@EugeneBuvard 3 жыл бұрын
Nope. Those are two different things. The World Wide Web was indeed created in CERN (how websites works mostly). The internet and its ancester ARPA Net was invented in US.
@rajdivecha
@rajdivecha 9 жыл бұрын
This makes it simple but the problem still exits - ProtonMail can potentially grab the private keys of the users when it creates them and store them on its server! The only way out is to learn about security, in this case PGP, and use the knowledge to generate the keys on your own and use them when sending emails. You can then use any email service.
@hantimagyar
@hantimagyar 9 ай бұрын
But if you trust them there is no more problem! Personally I trust PM and use it, and do not think that they do things you talk about. You have the right to do what you want. In the world exist honest people too, despite that there so many idiots...
@ziozionisi9159
@ziozionisi9159 7 жыл бұрын
You hold the lock and I hold the key.
@surelock3221
@surelock3221 7 жыл бұрын
That's what I said to my gf ;)
@mapachegordo6209
@mapachegordo6209 3 жыл бұрын
can somebdy tellme the name of all the apps at 10:59?
@MrHayada
@MrHayada 9 жыл бұрын
Isn't the RSA encryption already widely implemented? Almost everything that i use daily is encrypted and salted. And does this scenario require that Bob and Alice are both using Protonmail? to exchange the keys. Regardless of the above, the NSA has the means to decrypt or brute force their way if they wanted to. But i can understand how our digital footprint is being collected and making a business out of it is something that is happening. We can be judged for searches, comments and reads that we did. We need to rethink encryption, for the sake of privacy and humans, and for the sake of security and AI. But even if we did that, i can't see us being in a place better than the current one which we worked kind of well to get to.
@zellfaze
@zellfaze 9 жыл бұрын
What gets me is that he discussed how complex PGP is, and then appeared to describe how PGP works. I'm only 8 minutes in so far, but ProtonMail currently looks a whole lot like PGP....
@majorgnu
@majorgnu 9 жыл бұрын
>Regardless of the above, the NSA has the means to decrypt or brute force their way if they wanted to. It depends on the encryption. The NSA isn't staffed by wizards with anti-strong-crypto magic spells. Even if they were able to crack specific users' systems to extract their private keys, they would no longer be able to do mass surveillance without people finding out about it. The protonmail model is susceptible to mass key theft via cracking their systems. An attacker would be able to modify the code of their web-based cryptosuite in a way that leaks the private key, and then any user that logged in until they noticed the breach would have their private key leaked, and all of their previous communications compromised, including those deleted from the server, since it doesn't have perfect forward secrecy. This could also be done with a MitM attack that exploited either the TLS cryptosuite of the browser or server, or the CA trust model used to securely distribute the protomail code, which is inherently broken against established powers.
@zellfaze
@zellfaze 9 жыл бұрын
(Have now watched entire video) Agreed with joaorstm. When they started describing how asymmetric crypto worked I thought he would say he created a Firefox and Chrome extension that made easy the use of PGP on the existing powers-that-be email services. If I had a browser extension that added a "Encrypt" checkbox next to the send button in Gmail, Yahoo Mail, and Windows Live Mail, that would make my day. Such a system wouldn't be susceptible to the mass key theft attack that jaorstm describes, though the lack of perfect forward secrecy is still an issue.
@MrHayada
@MrHayada 9 жыл бұрын
joaorstm -You can't make %100 security, Whatever you make someone will have the chance to break, and the NSA is interested in breaking it and does have the wizards and magic spells in this case, Which are nothing more that resources and time.- -Protonmail swipes us and the companies that are providing us with services from the the issue of centralizing the process on the handlers which are the companies and leaves the burden on the users making it difficult to use the server-backdoor formula or th- I feel like I'm stating the obvious, Ditto would be and easier reply.
@MrHayada
@MrHayada 9 жыл бұрын
zellfaze Exactly, i thought of it as an extension, something close to Mega, but i assume that i have something wrong in my understanding, that's why i asked _'does this scenario require that Bob and Alice are both using Protonmail? to exchange the keys.'_ But why wouldn't the assumed extension be exposed to mass key theft? if you didn't see the source code wouldn't it be a possibility that the whole thing is layered?
@macrosoft1337
@macrosoft1337 9 жыл бұрын
But isnt the Mail written online and only secured via https? How does this make Sense?
@DerTypHinnerDir
@DerTypHinnerDir 9 жыл бұрын
He's avoiding the problematic questions. If the private key is in the users browser, how can he read his mail from another device? How to prevent, that he clears his local storage and looses his private key and therefore access to all his mail, without any option to restore it (which there can't be with this technology)? How to prevent sombody from intercepting during public key exchange, giving out his own public key and therefore decrypting, reading and reencrypting messages without anybody noticing? What he showed is easy to implement and nothing new and it doesn't solve the problems that prevent the widespread use of this technology.
@z.deutch1334
@z.deutch1334 6 жыл бұрын
And I'd like to know whether this scenario will make Protonmail useless: you use Protonmail but your friend uses Gmail, and the replies have a history trail, then what's the point of encryption if Gmail servers still get a copy of the conversation?
@9696Punk
@9696Punk 6 жыл бұрын
The private key is client-side generated with the users password. So if you log into the ProtonMail account on another device the private-key is generated locally again.
@SlykeThePhoxenix
@SlykeThePhoxenix 9 жыл бұрын
So if I send a message from my computer, the person replies and I want to read it from another computer, how do I do that if the key is generated at send time and not stored on the server?
@myrec8883
@myrec8883 9 жыл бұрын
SlykeThePhoxenix You have a problem. You will need to transfer that key somehow from one device to all of your devices using that service. Another problem is that you had to make new key every few months and again distribute it over to all of your devices by yourself. Maybe they could just let everyone who knows your last key to get the new one each few months, but that is just a unnecessary cryptographic hole.
@RoyManter
@RoyManter 9 жыл бұрын
which language is written in the sublime ss ?
@IdleGod
@IdleGod 9 жыл бұрын
S/MIME. We need to make generating and signing keys, as well as public key exchange easier, but it's already implemented in most email clients. I see major problems with Proton mail, primarily around portability. He is right, we need encrypted email, but Proton isn't the solution.
@benjamind.gordon
@benjamind.gordon 3 ай бұрын
Very Interesting! Viewing this in 2024 almost a decade later!
@randomdamian
@randomdamian Жыл бұрын
Simple question, how does Bob get the key without the server seeing the key? :)
@userteymouril
@userteymouril Жыл бұрын
از تلگرام سایت ادتلاین دانلود و در ایمپورت اوت لاین نصب میکنیم
@immjs
@immjs Жыл бұрын
8:00 Out of all the codes you could have taken, you chose the one for list item autocomplete
@brucewayne-cave
@brucewayne-cave 9 жыл бұрын
How do we know ProtonMail is not written with governmental backdoors? This all could be one giant trojan horse.
@DavidVoxDem
@DavidVoxDem 8 жыл бұрын
Even so, how can it be worse than what we have now ? I know for a fact that 75% of the users in my country entrust with their email the same company that gives us the news and weather. And that's the same country that doesn't have a single shop which doesn't sell contraband products.
@MatthewHolevinski
@MatthewHolevinski 7 жыл бұрын
Bruce Wayne relatively certain demoncrypt solves all related privacy concerns for everybody, generally speaking.
@nickjoeb
@nickjoeb 9 жыл бұрын
I like the idea and get where you are coming from but I think it would be better to have total transparency in all ways. Privacy is just a way to hide bad things.
@Eltoca21
@Eltoca21 9 жыл бұрын
How would Bob initially make contact and communicate with Alice if he did not know her? How would they both know each others keys?
@ivany5058
@ivany5058 8 жыл бұрын
if i send a protonmail to another server such as gmail or ymail how can the public user generate the encription key without invading the privacy?
@jaafersa
@jaafersa 7 жыл бұрын
Well, a key isn't made if you wanna communicate with a Gmail or Yahoo user. Rather, you write the email, put a password on it, and then Protonmail sends a link to that user. In order to see the email, the user needs to put in the password that the author set up.
@Froggykaos
@Froggykaos 9 жыл бұрын
The biggest problem with this solution is it requires both emails to be on the same service Proton Mail. There is basically no way to have email encryption that works universally.
@moceanpicture
@moceanpicture 7 жыл бұрын
So if I use proton mail, email someone who has gmail or some mainstream email account, my email is no longer hidden? What's the point unless you can get all your friends, family, and colleagues (corporations) on board?
@uniqhnd23
@uniqhnd23 5 жыл бұрын
There's an option to send them an encrypted email, but they'll need a password to decrypt it. Either way, just tell them to start using protonmail dude. The more people you get on board, the better.
@hantimagyar
@hantimagyar 9 ай бұрын
Even in this case is better option. Google not only read your emails but also store IP addresses which are the key point to create your profile. If you do not use their services they cannot do this.
@BudIce32oz
@BudIce32oz 8 жыл бұрын
Is there anyone else on here that's in the least bit concerned with the fact that CERN is a part of this?
@jaafersa
@jaafersa 7 жыл бұрын
First off, they worked for CERN, and that's it. That is the only connection they have with CERN, I believe. And even if CERN controls this program, what's wrong with that?
@dierks67
@dierks67 6 жыл бұрын
The US Gov contributed to the development of Tor.
@brienmaybe.4415
@brienmaybe.4415 5 жыл бұрын
@@jaafersa "old habits die hard" meaning if one worked for cern-which requires even the janitors to have a clearance, surely that means a former employee doesn't just "give up" the ideals of cern unless he's a whistleblower. And if he's a whistleblower, I'm more than likely sure he wouldn't be going around making a new email and privacy service and Ted talks which are basically just a convention to sell new ideas, products and technology in front of a bunch of rich people.
@vgmbbop
@vgmbbop 9 жыл бұрын
Andy yen, First of all i would like to thank you for your idea, its much needed in this wolds around us that is built in plain glasses. But please stop giving free service and ask the users to pay for the privacy and start making your own revenue without relying on donations and charity. A person who understands the value of privacy will definitely pay.
@krishnapatni
@krishnapatni 9 жыл бұрын
There was a piece of story where it was reported that the RSA key generation algorithm that Andy mentioned also had a backdoor where the Government could peek into. And this backdoor has been since many years.
@chapstic593
@chapstic593 9 жыл бұрын
You mean the heart bleed bug. Which is what happened to googles server that was advertising the keys accidently . This is using md5 rsa encryption. Another computer sends you the code to used to encrypt the mail. Your computer after its encrpted it doesnt know how to decrypt it because it was not sent the other half of the key.
@krishnapatni
@krishnapatni 9 жыл бұрын
no ***** , way before that actually. www.theverge.com/2013/12/20/5231006/nsa-paid-10-million-for-a-back-door-into-rsa-encryption-according-to
@phizicks
@phizicks 8 жыл бұрын
um, isn't logging into the webmail system (protonmail) not have the key to encrypt your mail before sending to the receiver actually on the server? There's so many plugins for PGP these days into mail clients making it easier to encrypt on the fly. forget using external encrypted services when the data you send ends up in the clear on their servers and they have your private key to encrypt it. encrypt it locally, that's the goal.
@skybird3809
@skybird3809 8 жыл бұрын
that's the point, they are encrypting it locally
@HiAdrian
@HiAdrian 9 жыл бұрын
Who thinks their email is private these days? From other regular people? Yes. From the government and service providers? No, but that's nothing new. Anyway, I approve of any efforts in this direction. If one of the parties doesn't use encryption then the whole exchange is open to prying eyes; So making encryption easier to set up is important. You could always help your relatives set something like this up, but it'll be your lawyer, bank etc. that you want to see using this technology without lending a hand!
@ghostdoggg
@ghostdoggg 8 жыл бұрын
but, the decription (private) key is still stored on the protonmail servers, isn't it? so if anyone gets access to that server, they can probably obtain both the encrypted emails and decryption keys. i think the only way to be sure is encrypting the email localy and only then passing the encrypted data to a mail service.
@skybird3809
@skybird3809 8 жыл бұрын
no, the whole point of this is that it's stored on your computer, not their servers
@hantimagyar
@hantimagyar 9 ай бұрын
@@skybird3809 In fact, it is not stored. Your password is used to generate the key.
@t1993ct2006c
@t1993ct2006c 8 жыл бұрын
What is M'Go
@codeinequeen649
@codeinequeen649 5 жыл бұрын
I can confirm.
@alexlototzky8909
@alexlototzky8909 8 жыл бұрын
fantastic
@MichaelPickles
@MichaelPickles 9 жыл бұрын
It would be nice to host my own photon mail server. I already have my own zimbra server and will be building more in xen server
@chris123213chris
@chris123213chris 9 жыл бұрын
Not to be rude or anything, I got so many Cloud Atlas vibes. He looks like the people from Neo Seoul
@noxxi
@noxxi 7 жыл бұрын
What about ProtonMail?
@noxxi
@noxxi 7 жыл бұрын
Nvm. I guess lets not comment before watching the entire video.
@victors8718
@victors8718 6 жыл бұрын
I use it too! :)
@jaredberelowitz194
@jaredberelowitz194 7 жыл бұрын
@hillary clinton
@MatthewHolevinski
@MatthewHolevinski 7 жыл бұрын
Jared Berelowitz lol
IQ Level: 10000
00:10
Younes Zarou
Рет қаралды 12 МЛН
Викторина от МАМЫ 🆘 | WICSUR #shorts
00:58
Бискас
Рет қаралды 5 МЛН
The Internet is on fire | Mikko Hypponen | TEDxBrussels
19:17
TEDx Talks
Рет қаралды 239 М.
William McDonough: Cradle to Cradle
8:22
The Beautiful Truth
Рет қаралды 7 М.
Think Fast, Talk Smart: Communication Techniques
58:20
Stanford Graduate School of Business
Рет қаралды 39 МЛН
The Unhackable Email Service | Freethink Coded
5:50
Freethink
Рет қаралды 1,3 МЛН
How not to take things personally? | Frederik Imbo | TEDxMechelen
17:37
The Skill of Humor | Andrew Tarvin | TEDxTAMU
19:17
TEDx Talks
Рет қаралды 14 МЛН
تجربة أغرب توصيلة شحن ضد القطع تماما
0:56
صدام العزي
Рет қаралды 64 МЛН
КРУТОЙ ТЕЛЕФОН
0:16
KINO KAIF
Рет қаралды 7 МЛН
Samsung vs iPhone ☠️ #shorts
0:18
My Tech
Рет қаралды 7 МЛН
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 1,2 МЛН